Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-17104 |
|
Information Disclosure in fiyo (CVE-2017-17104)
vulnerability in fiyo (CVE-2017-17104). Confidential information can be exposed externally.
|
| CVE-2017-17103 |
|
SQL Injection in sqli (CVE-2017-17103)
SQL injection in sqli (CVE-2017-17103). Successful exploitation can lead to full system takeover.
|
| CVE-2017-17102 |
|
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
|
| CVE-2015-3934 |
|
SQL Injection in sqli (CVE-2015-3934)
SQL injection in sqli (CVE-2015-3934). Successful exploitation can lead to full system takeover.
|
| CVE-2014-9148 |
|
Vulnerability in fiyo (CVE-2014-9148)
vulnerability in fiyo (CVE-2014-9148). Successful exploitation can lead to full system takeover.
|
| CVE-2014-9147 |
|
Information Disclosure in fiyo (CVE-2014-9147)
vulnerability in fiyo (CVE-2014-9147). Confidential information can be exposed externally.
|
| CVE-2017-13778 |
|
Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.
Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.
|
| CVE-2017-11631 |
|
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
|
| CVE-2017-11630 |
|
Path Traversal in path-traversal (CVE-2017-11630)
path traversal in path-traversal (CVE-2017-11630). Data can be tampered with by attackers.
|
| CVE-2017-11418 |
|
SQL Injection in sqli (CVE-2017-11418)
SQL injection in sqli (CVE-2017-11418). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11419 |
|
SQL Injection in sqli (CVE-2017-11419)
SQL injection in sqli (CVE-2017-11419). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11417 |
|
SQL Injection in sqli (CVE-2017-11417)
SQL injection in sqli (CVE-2017-11417). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11416 |
|
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
|
| CVE-2017-11415 |
|
SQL Injection in sqli (CVE-2017-11415)
SQL injection in sqli (CVE-2017-11415). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11414 |
|
SQL Injection in sqli (CVE-2017-11414)
SQL injection in sqli (CVE-2017-11414). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11413 |
|
SQL Injection in sqli (CVE-2017-11413)
SQL injection in sqli (CVE-2017-11413). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11412 |
|
SQL Injection in sqli (CVE-2017-11412)
SQL injection in sqli (CVE-2017-11412). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11354 |
|
SQL Injection in sqli (CVE-2017-11354)
SQL injection in sqli (CVE-2017-11354). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8853 |
|
Path Traversal in path-traversal (CVE-2017-8853)
path traversal in path-traversal (CVE-2017-8853). Data can be tampered with by attackers.
|
| CVE-2017-7625 |
|
Code Injection in fiyo (CVE-2017-7625)
code injection in fiyo (CVE-2017-7625). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6823 |
|
Vulnerability in fiyo (CVE-2017-6823)
vulnerability in fiyo (CVE-2017-6823). Successful exploitation can lead to full system takeover.
|